<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"
"http://www.w3.org/TR/REC-html40/loose.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<title></title>
</head>
<body style="font-family:Arial;font-size:14px">
<p>Tx to Mark Leiser for fascinating input!<br>
<br>
Milton,<br>
Tx for laying this out. I agree we have to be strategic - and I would add consistent with NCSG's history and advocacy on this topic too. We have a long history on WHOIS and privacy.<br>
<br>
<em>So let me ask the strategic questions: <strong>where are the other stakeholder groups (and relevant other groups) on these 4</strong> options? Could you tell us who is backing each of the options below?</em><br>
<br>
In particular, where are other SGs with whom NCSG EPDP has been working most closely over the years? Judging from a meeting I dropped into in Marrakech 2019, that would be Registrars and Registries. <em><strong>Where are the Rys and Rrs on these four options?</strong></em><br>
<br>
It would also be useful to know: <em>Is there a split between those in EU/comprehensive data protection countries including Brazil, Canada and Japan and the sectoral privacy countries like the US? Is there a legal split or are the EPDP participants of the SGs pretty aligned?</em><br>
<br>
<strong><em>Tx Milton, and to all NCSG EPDP members who would like to respond!<br>
Best, Kathy</em></strong><br>
<br>
<br>
Quoting "Mueller, Milton L" <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a>>:<br>
<br>
> So I think we have exchanged views and have a pretty good idea of<br>
> where people stand and what the issues are.<br>
> The next step is to define a position in the EPDP that all of our<br>
> members can adhere to.<br>
> Let me emphasize that defining a viable position is strategic and not<br>
> simply a matter of standing up for some abstract principle.<br>
><br>
> I will try to identify the set of real options below<br>
><br>
> Option 1<br>
> ------------<br>
> Under the phase 1 agreement there is no requirement to differentiate<br>
> between legal and natural persons, but Contracted Parties (CPs) can<br>
> do so if they want to. We are working on possible "guidance" for CPs<br>
> who do try to differentiate.<br>
> One possibility is to leave things as they are.<br>
> No guidance. No requirement to differentiate. Let the status quo<br>
> stand. CPs can do whatever they want.<br>
> Benefits: most data will probably remain redacted<br>
> Risks/problems:<br>
> - we are already working on guidance, this may no longer be an option<br>
> - some registrars could impose differentiation on their customers<br>
> - GAC, including European Commission, IPC, BC, ALAC, SSAC will be<br>
> unhappy and apparent lack of consensus could lead to board or<br>
> legislative override<br>
><br>
> Option 2:<br>
> ------------<br>
> (Stephanie's approach)<br>
> Develop Guidance, but make it non-binding<br>
> No legal or natural differentiation, focus on presence or absence of<br>
> personal data<br>
> Registrant must make attestations re personal data; more difficult<br>
> and costly process<br>
> CP involvement in and liability for decisions<br>
><br>
> Option 3:<br>
> -----------<br>
> (Milton's approach)<br>
> Develop Guidance, but make it non-binding<br>
> Ask for self-designation as legal at point of registration;<br>
> registrant is informed of consequences<br>
> CP can alter record only at request of Registrant<br>
> CP liability and responsibility for contents of reg records is minimized<br>
><br>
> Option 4:<br>
> ------------<br>
> Develop guidance for differentiation and make it a requirement<br>
> Many different options under here.<br>
><br>
> This is not an exhaustive list, but it will get us started.<br>
> We need to move beyond posturing and offer specific proposals that<br>
> can gain traction in the actual EPDP group.<br>
><br>
> Dr. Milton L Mueller<br>
> Georgia Institute of Technology<br>
> School of Public Policy<br>
> [IGP_logo_gold block]<br>
<br></p>
</body>
</html>